Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Maxthon

First CVE: May 2, 2005Active for: 21 yearsTotal CVEs: 10
26.8
VTI Score
Low

Maxthon develops a lightweight web browser and cloud-based browsing platform, with a narrowly focused vulnerability footprint centered on its browser product and related services. The recurring exposure reflects typical browser-implementation challenges: cross-site scripting, buffer boundary violations, improper access control, and input-neutralization weaknesses that arise in rendering and script-execution contexts, though public exploit code has been developed for vulnerabilities affecting this vendor. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Maxthon over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2005
21 years ago
Most Recent CVE
Oct 29, 2019
2,460 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-3667MEDIUM
Stack-based buffer overflow in Maxthon Browser 2.0 and earlier allows remote attackers to execute arbitrary code via a long Content-type HTTP header.
Aug 13, 20086.829NOYES
CVE-2019-16647HIGH
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
Oct 29, 20197.225NONO
CVE-2010-5246MEDIUM
Multiple untrusted search path vulnerabilities in Maxthon Browser 1.6.7.35 and 2.5.15 allow local users to gain privileges via a Trojan horse (1) RSRC32.dll or (2) dwmapi.dll file
Sep 7, 20126.920NONO
CVE-2014-1449MEDIUM
The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API.
Dec 25, 20145.019NONO
CVE-2005-1091HIGH
Maxthon 1.2.0 and 1.2.1 allows remote attackers to bypass the security ID and use restricted plugin API functions via script that includes the max.src file into the source page.
May 2, 20057.519NONO
CVE-2005-0905LOW
Maxthon 1.2.0 allows remote malicious web sites to obtain potentially sensitive data from the search bar via the m2_search_text property.
May 2, 20052.618NOYES
CVE-2005-1090MEDIUM
Directory traversal vulnerability in the readFile and writeFile API for Maxthon 1.2.0 and 1.2.1 allows remote attackers to read or write arbitrary files.
May 2, 20056.418NONO
CVE-2009-3018MEDIUM
Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cro
Aug 31, 20094.316NONO
CVE-2009-3006MEDIUM
Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the vict
Aug 28, 20094.315NONO
CVE-2006-6985MEDIUM
Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that refere
Feb 9, 20075.015NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
10%
70%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (10.0%)
Unknown9 (90.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (10.0%)
High0 (0.0%)
Unknown9 (90.0%)
User Interaction
None1 (10.0%)
Unknown9 (90.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High1 (10.0%)
None0 (0.0%)
Unknown9 (90.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
20.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Maxthon.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Maxthon — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Maxthon's Products

View all 1 CNAs →

Top CWEs